Flow-based statistical aggregation schemes for network anomaly detection

被引:0
|
作者
Song, Sui [1 ]
Ling, Li [1 ]
Manikopoulo, C. N. [1 ]
机构
[1] New Jersey Inst Technol, Dept Elect Engn, Newark, NJ 07102 USA
关键词
flow; aggregation; neural network classifier; network intrusion detection system;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present a novel Flow-based Statistical Aggregation Schemes (FSAS) for Network Anomaly Detection. An IP flow is a unidirectional series of IP packets of a given protocol, traveling between a source and destination, within a certain period of time. Based on "flow" concept, we developed a flow-based aggregation technique that dramatically reduces the amount of monitoring data and handles high amounts of statistics and packet data. FSSAS sets up flow-based statistical feature vectors and reports to Neural Network Classifier. Neural Classifier uses Back-Propagation networks to classify score metric of each flow. FSAS can detect both bandwidth type DOS and protocol type DOS. Moreover, flow here could be any set of packets sharing certain common property as "flow key". FSAS configures flow flexibly to provide security from network level to application level (IP, TCP, UDP, HTTP, FTP...), and different aggregation schemes, such as server -based, client-based flow. This novel IDS has been evaluated by using DARPA 98 data and CONEX test-bed data. Results show the success in terms of different aggregation schemes for both datasets.
引用
下载
收藏
页码:786 / 791
页数:6
相关论文
共 50 条
  • [31] Flow-based Malware Detection Using Convolutional Neural Network
    Yeo, M.
    Koo, Y.
    Yoon, Y.
    Hwang, T.
    Ryu, J.
    Song, J.
    Park, C.
    2018 32ND INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2018, : 910 - 913
  • [32] Detection of slow port scans in flow-based network traffic
    Ring, Markus
    Landes, Dieter
    Hotho, Andreas
    PLOS ONE, 2018, 13 (09):
  • [33] Flow-based anomaly detection in high-speed links using modified GSA-optimized neural network
    Mansour Sheikhan
    Zahra Jadidi
    Neural Computing and Applications, 2014, 24 : 599 - 611
  • [34] Flow-based anomaly detection in high-speed links using modified GSA-optimized neural network
    Sheikhan, Mansour
    Jadidi, Zahra
    NEURAL COMPUTING & APPLICATIONS, 2014, 24 (3-4): : 599 - 611
  • [35] Anomaly Detection Using Normalizing Flow-Based Density Estimation and Synthetic Defect Classification
    Oh, Seungmi
    Kim, Jeongtae
    IEEE ACCESS, 2024, 12 : 75873 - 75887
  • [36] Flow-based Network Intrusion Detection Based on BERT Masked Language Model
    Nguyen, Loc Gia
    Watabe, Kohei
    PROCEEDINGS OF THE INTERNATIONAL CONEXT STUDENT WORKSHOP 2022, CONEXT-SW 2022, 2022, : 7 - 8
  • [37] Conceptual integration of flow-based and packet-based network intrusion detection
    Schaffrath, Gregor
    Stiller, Burkhard
    RESILIENT NETWORKS AND SERVICES, 2008, 5127 : 190 - 194
  • [38] Flow Simulator - a flow-based network simulator
    Drzewiecki, Lukasz
    Antoniak-Lewandowska, Monika
    EUROCON 2007: THE INTERNATIONAL CONFERENCE ON COMPUTER AS A TOOL, VOLS 1-6, 2007, : 2124 - 2128
  • [39] Template-based Feature Aggregation Network for industrial anomaly detection
    Luo, Wei
    Yao, Haiming
    Yu, Wenyong
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 131
  • [40] Anomaly Characterization in Flow-Based Traffic Time Series
    Sperotto, Anna
    Sadre, Ramin
    Pras, Aiko
    IP OPERATIONS AND MANAGEMENT, PROCEEDINGS, 2008, 5275 : 15 - 27